Security

How to permanently remove accounts remaining after removing passwd file?

a212830
Champion

Hi,

I am in the process of rebuilding my dev environment, and am taking over an existing search-head that wasn't being used. I upgraded to 6.1.3, and then renamed the passwd file, so that all the old accounts were removed. However, there are still a number of ldap-based accounts appearing, and if I try to delete them via the gui, a message appears saying that "user account does not exist". Is there another place where they need to be removed from? I looked in the passwd file, and they are not present.

Tags (2)

hsesterhenn_spl
Splunk Employee
Splunk Employee

As far as I understand the docs directories in etc/users are automatically created as long as you can successfully log in via LDAP.

HTH,

Holger

0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...